Privacy Policy
Last updated: June 2026
This Privacy Policy describes how Nivoryx Private Limited (“Nivoryx”, “we”, “us”) handles information when you use the Nivoryx mobile application, this website, and related services (collectively, the “Services”).
1. Scope
This policy applies to information processed through the Services. It does not cover third-party websites or services that we do not control.
2. Information We May Collect
Depending on how you use the Services and your device or browser settings, we may process:
- Account data: name, email address, phone number, and authentication identifiers from your identity provider (e.g., email/password or federated sign-in such as Google).
- Device and technical data: device model, OS version, app version, diagnostic logs, crash reports, push notification tokens, and network connectivity status as needed to operate and improve the service.
- Product usage: interactions with features, configuration of connected devices, sensor and telemetry data (such as water levels, schedules, or device status), and usage information needed for reliability and security.
- Location: only if you grant permission and where a feature explicitly requires it (for example, Bluetooth device discovery on older Android versions).
- Bluetooth and local network: used to discover and communicate with supported hardware when you initiate pairing or control flows.
- Support interactions: messages you send through in-app support chat; optional voice input when you choose to use it; and camera access when you scan a QR code for pairing.
- Payment-related data: subscription and purchase records. Payment card details are processed by our payment provider (Razorpay); we do not store full card numbers.
- Website data: cookies and similar technologies when you use this site. Necessary cookies support core functionality; analytics and marketing cookies are used only with your consent via the cookie preferences banner.
3. How We Use Information
We use information to provide and secure the Services, authenticate users, operate connected devices, send service notifications, troubleshoot issues, provide customer support, comply with law, and improve product quality. We do not sell your personal information.
4. Legal Bases (Where Applicable)
Where GDPR or similar laws apply, we rely on bases such as contract (providing the service), legitimate interests (security and improvement), consent (where required, including optional cookies and permissions), and legal obligation.
5. Sharing
We may share information with service providers who assist us (hosting, analytics, crash reporting, authentication, payments, and customer support) under contracts that limit their use. Examples include cloud hosting (AWS), payment processing (Razorpay), error monitoring (Sentry), and sign-in or messaging services (Google). We may disclose information if required by law or to protect rights and safety.
6. Retention
We retain information as long as needed for the purposes above and as required by law. Technical logs may be retained for shorter periods. Connected device telemetry from DASS installations is retained for up to 18 months in raw form; telemetry is severed from your account within 30 days of verified device return.
7. Connected device telemetry (DASS)
When you use a Nivoryx-managed device under our Device-as-a-Subscription Service program, we process telemetry (for example tank level, pump run times, connectivity status, and alert events) to operate the service, billing, and safety features. Purposes and retention are limited to those described here and in the DASS Subscription Agreement.
8. Security
We implement administrative, technical, and organizational measures designed to protect personal information, including encryption in transit (TLS) and access controls. No method of transmission or storage is completely secure.
9. Your Rights
Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Contact us to exercise these rights.
To make a request, email privacy@nivoryx.com.
10. Children
The Services are not directed at children under 13 (or the minimum age in your jurisdiction). Do not provide personal information if you do not meet the age requirement.
11. International Transfers
If we transfer personal information across borders, we use appropriate safeguards where required by law.
12. Changes to This Policy
We may update this Privacy Policy. We will post the updated version on this page, in the app bundle, or notify you as appropriate for material changes.
13. Contact
Privacy inquiries:
- Email: privacy@nivoryx.com
- Data Protection Officer & Grievance Officer: names to be published before production launch (business#1 W4)
- Phone: +91 92174 05503
- Address: Delhi NCR, India